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Abstract. Deontic logic is a very well researched branch of mathemati¬ 
cal logic and philosophy. Various kinds of deontic logics are considered for 
different application domains like argumentation theory, legal reasoning, 
and acts in multi-agent systems. In this paper, we show how standard 
deontic logic can be used to model ethical codes for multi-agent systems. 
Furthermore we show how Hyper, a high performance theorem prover, 
can be used to prove properties of these ethical codes. 


1 Introduction 

Deontic logic is a very well researched branch of mathematical logic and phi¬ 
losophy. Various kinds of deontic logics are considered for different application 
domains like argumentation theory, legal reasoning, and acts in multi-agent sys¬ 
tems [8]. 

This paper applies automated reasoning in standard deontic logic (SDL) to a 
problem in multi-agent systems. For this, we follow the example from [5] where 
reasoning with ethical codes is presented. Instead of implementing a reasoning 
system for deontic logic directly, we rely on the first order reasoning system 
Hyper |l4j, which uses the hypertableau calculus from [3|. This has the advantage 
that reasoning in deontic logic can be embedded easily into other applications 
for which Hyper is already an inference system (e.g. the LogAnswer system GO)- 

SDL corresponds to the modal logic K with a seriality axiom. Due to the 
fact that modal logic K is (more or less) a notational variant of description logic 
ACC, deontic logic can be translated into it [7|. Since Hyper offers a decision 
procedure for various description logics, it can be employed for reasoning in SDL. 

In Section [2] we shortly depict the reasoning framework, and in Section [3] we 
show how to model our small example. This hopefully documents the applica¬ 
bility of reasoning with SDL in multi-agent systems. 


2 Automated Reasoning for Standard Deontic Logic 

Standard deontic logic (SDL) is obtained from the well-known modal logic K 
by adding the seriality axiom D: OP —>■ OP. In this logic, the D-operator is 
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interpreted as ‘it is obligatory that’ and the 0 as ‘it is permitted that’. The 
0-operator can be defined by 0 P = - 0 _i .P. The seriality axiom in SDL states 
that, if a formula has to hold in all reachable worlds, then there exists such a 
world. With the deontic reading of □ and 0 this means: Whenever the formula 
P ought to be, then there exists a world where it holds. In consequence, there 
is always a world, which is ideal in the sense that all the norms formulated by 
‘the ought to be’-operator hold. 

Deontic logic is the logic of choice when formalizing knowledge about norms 
like the representation of legal knowledge or ethical codes for agents. However, 
there are only few automated theorem provers specially dedicated for deontic 
logic and used by deontic logicians (see |1|2| ). Nonetheless, numerous approaches 
to translate modal logics into (decidable fragments of) first-order predicate logics 
are stated in the literature. A nice overview including many relevant references 
is given in [121- 

In this paper, we use the first order predicate logic theorem prover Hyper [14] 
to handle SDL knowledge bases. By using the well-known translation of modal 
logic into description logic [11] (called p in the sequel) and the fact that Hyper 
offers a decision procedure for the description logic SH1Q [4], we are able to 
process SDL efficiently. In the following, SDL is translated into ACC, which is a 
subset of SH1Q. 


Transformation from SDL into A.CC 

For a normative system consisting of the set of deontic logic formulae TV = 
{Pi,..., P„}, the translation ip is defined as the conjunctive combination of the 
translation of all deontic logic formulae in TV: 

<^(TV) = ip(Fi) n ... n <p(F n ) 

Note that p(N) does not yet contain the translation of the seriality axiom. 
As shown in [9], the seriality axiom can be translated into the TBox 

T={TE 3r.T } 

with r the atomic role introduced by the mapping <p. 

For our application, the result of the translation of a normative system A f and 
the seriality axiom is an ACC knowledge base <P(Af) = (T, -4), where the TBox T 
consists of the translation of the seriality axiom and the ABox A = {((/?(TV))(a)} 
for a new individual a. In description logics, performing a satisfiability test of a 
concept C w.r.t. a TBox is usually done by adding a new individual a together 
with the ABox assertion C(a). For the sake of simplicity, we do this construction 
already during the transformation of <P by adding (<^(TV))(a) to the ABox. 

An advantage of the translation of deontic logic formulae into an ACC knowl¬ 
edge base is the existence of a TBox in ACC. This makes it possible to add further 
axioms to the TBox. For example we can add certain norms that we want to be 
satisfied in all reachable worlds into the TBox. 
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Reasoning Tasks 

With the help of Hyper, we can solve the following interesting reasoning tasks: 

Consistency checking of normative systems: In practice, normative systems can 
be very large. Therefore it is not easy to see, if a given normative system is 
consistent. The Hyper theorem prover can be used to check consistency of a 
normative system Af. 

Evaluation of normative systems: Given several normative systems, we use Hy¬ 
per to find out for which normative system a desired outcome is guaranteed. 

3 An Example from Multi-agent Systems 

In multi-agent systems, there is a challenging area of research, namely the for¬ 
malization of ‘robot ethics’. It aims at defining formal rules for the behavior of 
agents and to prove certain properties. As an example consider Asimov’s laws, 
which aim at regulating the relation between robots and humans. In [5], the 
authors depict a small example of two surgery robots obeying ethical codes con¬ 
cerning their work. These codes are expressed by means of MADL, which is an 
extension of standard deontic logic with two operators. In [10] . an axiomatization 
of MADL is given. Further it is asserted, that MADL is not essentially different 
from standard deontic logic. This is why we use SDL to model the example. 


Formalization in SDL 

In our example, there are two robots agl and ag2 in a hospital. For the sake 
of simplicity, each robot can perform one specific action: agl can terminate a 
person’s life support and ag2 can delay the delivery of pain medication. In [5], 
four different ethical codes J, J*, O and O * are considered: 

- “If ethical code J holds, then robot agl ought to take care that life support 
is terminated.” This is formalized as: 

J —> Oact(agl , term) 

- “If ethical code J* holds, then code J holds, and robot ag2 ought to take 
care that the delivery of pain medication is delayed.” This is formalized as: 

J* —> J A J* —> Dact(ag2 , delay) 

- “If ethical code O holds, then robot ag2 ought to take care that delivery of 
pain medication is not delayed.” This is formalized as: 


O —»• D^act(ag2, delay) 
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- “If ethical code O* holds, then code O holds, and robot agl ought to take 
care that life support is not terminated.” This is formalized as: 

O* —> O A O* —» D~>act(agl , term) 

Further we give a slightly modified version of the evaluation of the acts of the 
robots, as stated in 0, where (+!!) denotes the most and (—!!) the least desired 
outcome. Note that terms like (+!!) are just propositional atomic formulae here. 


act[ag 1, term) A act(ag2, delay) —► (—!!) (1) 

act{agl , term) A ~^act(ag2, delay) —>• (—!) (2) 

->act{agl , term) A act(ag2, delay) —>• (—) (3) 

act(ag 1, term) A ^act(ag2, delay) —» (+!!) (4) 


These formulae evaluate the outcome of the robots’ actions. It makes sense 
to assume, that this evaluation is effective in all reachable worlds. This is why 
we add formulae stating that formulae 0 0 hold in all reachable worlds. For 
example, for m we add: 

\3(act(agl, term) A act(ag2 , delay) —> (—!!)) (5) 

Since our example does not include nested modal operators, the formulae of the 
form <[5|) are sufficient to spread the evaluation formulae to all reachable worlds. 
The normative system TV formalizing this example consists of the formalization 
of the four ethical codes and the formulae for the evaluation of the robots actions. 


Reduction to a Satisfiability Test 

A possible query would be to ask if the most desirable outcome (+!!) will come 
to pass if ethical code O* is operative. This query can be translated into a 
satisfiability test. If Af A O* A <>-'(+!!) is unsatisfiable, then ethical code O* 
ensures outcome (+!!). 

Hyper can be used for this satisfiability test. We obtain the desired result 
namely that (only) ethical code O* leads to the most desirable behavior (+!!). 


Experiment 

We formalized this example and tested it with the Hyper theorem prover as 
described above. Since all formalizations are available in ACC, we used the de¬ 
scription logic reasoner Pellet [13J to compare the performance with Hyper. It 
took Pellet 2.548 seconds and Hyper 2.596 seconds to show the unsatisfiability. 

Additional experiments can be found in [J. For the examples we considered, 
the runtimes of Pellet and Hyper are comparable. Further investigation and 
comparison with other modal and/or description logic reasoning tools is required 
and subject of future work. 
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4 Conclusion 

In this paper, we illustrated with the help of an example how to use standard 
deontic logic to model ethical codes for multi-agent systems. For normative sys¬ 
tems described with deontic logic, there is a translation into description logic 
concepts. These concepts can be checked automatically by automated theorem 
provers. We used the Hyper theorem prover to prove that a specified desired 
outcome is guaranteed, if a certain ethical code is operative. 
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